Skip to content

Trust and security

You’re in charge. And you can check it.

Giving an AI access to your email and your data is a serious decision. Here is how AIRON works inside, with what is already in place and what isn’t yet.

The journey of an email

What happens, and where, from the moment an email arrives until the reply goes out.

  1. 01

    It reaches your inbox

    Gmail, Outlook or any IMAP mailbox. Your mailbox is still yours.

    Your email provider

  2. 02

    It is stored and indexed

    The content AIRON needs is stored on our servers and indexed so it can be searched.

    Frankfurt (EU) · IONOS and Google Cloud

  3. 03

    The AI drafts a proposal

    The language model prepares the draft with your company’s context and tone.

    United States · OpenAI

  4. 04

    A person decides

    The draft waits in Approvals. You edit it, approve it or reject it with a reason.

    Your team

  5. 05

    It goes out and is recorded

    It is sent once, from your mailbox and with your signature, and recorded in Activity.

    Your mailbox · Activity

Who decides what goes out

Two different rules depending on who starts the action.

What AIRON starts on its own

Replies to incoming emails, flow steps that send something out and posts proposed by AIRON. They always wait for a person: they can be blocked, but never left on automatic.

What you ask for

In the chat or on WhatsApp, anything that goes to third parties, is tax-related or spends money asks for approval by default. Internal things happen right away and, for events and AIRON CRM, can be undone. The account administrator can adjust each tool; the Alegra invoice always asks for approval.

Action By default
Send an email Asks for approval
Issue an invoice (Facturales) Asks for approval
Pause or change an Ads campaign Asks for approval
Post on Instagram Asks for approval
Create an event with guests Asks for approval
Changes in GitHub, Vercel, Supabase or Dropbox Asks for approval
Create a task or note in AIRON CRM Happens right away
Create an event without guests Happens right away
Read, search and summarise Happens right away

Approving is a permission

Only people with the approval permission can send, whether from the inbox, the chat or by replying “yes” on WhatsApp. And each draft is sent only once, on the version you saw.

Who sees what

Your chatCompany approvalsConnectors and permissions
You Yes Yes Depends on role
Your colleagues No Yes Depends on role
Your Superadmin No Yes Yes
Other companies No No No

There are two roles: Superadmin, who manages the team and permissions, and Member. Your chat is private: AIRON never quotes what you wrote to anyone. With Microsoft 365, your drafts go out from your own mailbox and only you see them.

Your company, isolated from the rest

Each company has its own space and every query —including document searches and memory— is filtered by that space before returning anything. If the filter cannot be applied, the query fails instead of returning too much.

Your data, yours

  • Download it whenever you want

    All your data as a ZIP from Management.

  • If you leave, it’s deleted

    Conversations, memory, files and credentials. Only what the law requires is kept; backups roll over within 30 days.

  • Encrypted credentials

    Your connector credentials are stored encrypted and tied to your company; you can revoke them whenever you want.

EU AI Act

  • You always know it’s AI

    A notice in the chat, a footer in emails and on WhatsApp, and a verifiable signature on the PDFs and images it generates.

  • Limited risk, monitored

    An automatic control prevents adding a high-risk purpose without first opening the conformity file.

  • AI training

    AIRON Academy records each person’s training, which is what Article 4 of the Act asks for.

Operational security

  • Encrypted connections (TLS 1.2 and 1.3) with HSTS
  • Server logs without tokens or secrets
  • Encrypted off-server backups, with tested restores
  • Blocking of repeated login attempts
  • Vulnerability disclosure channel (security.txt)
  • Data processing agreement accepted and versioned from the first login

What we don’t have yet

  • ISO 27001, SOC 2 or ENS certifications
  • External penetration test
  • Language model processed in the EU
  • Signed processing agreements with every provider (in progress)
  • Automatic anonymisation of personal data before the AI (in development, not yet active)

If you need any of this to decide, write to security@airon.team and we’ll tell you where it stands.